Back to skill

Security audit

outlook-mail-reader

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it asks for broad browser-control access to a logged-in Outlook session and uses a mutable MCP dependency, so users should review it carefully before installing.

Install only if you are comfortable letting the agent control a logged-in browser session that can read Outlook mail. Prefer using a separate Chrome profile or separate OS account just for Outlook, close unrelated tabs, remove the MCP config when finished, and pin or vet the `chrome-devtools-mcp` package instead of using `@latest`.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Unpinned Third-Party Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35-43
Vulnerability Type: Supply-chain risk caused by mutable dependency execution
Risk Level: High

Vulnerable Code

json
"command": "npx",
"args": [
  "chrome-devtools-mcp@latest",
  "--autoConnect"
]

Technical Analysis

The recommended MCP configuration invokes chrome-devtools-mcp@latest through npx. The latest tag is mutable and does not identify a specific, previously reviewed release. Depending on the local npm configuration and cache state, npx can download and execute the current package version when the OpenClaw gateway starts.

The executed dependency is outside the audited project and receives browser-control capabilities through Chrome DevTools. Consequently, an upstream package compromise, malicious package publication, or unsafe future release could change the effective executable payload without any modification to this Skill.

This is an insecure dependency-loading pattern. The available evidence does not establish that the current upstream package is malicious, but the configuration creates a direct supply-chain execution path.

Attack Path

  1. The user adds the documented MCP server configuration to OpenClaw.
  2. The user restarts the OpenClaw gateway.
  3. OpenClaw invokes npx with chrome-devtools-mcp@latest.
  4. npx resolves the mutable latest tag and may download the corresponding package.
  5. A compromised or maliciously changed package executes locally as the user running OpenClaw.
  6. The package uses --autoConnect to attach to the remote-debugging-enabled Chrome instance.
  7. The malicious dependency can attempt to inspect or manipulate authenticated browser tabs and data available through the DevTools connection.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the OpenClaw process. Because the package is configured as a browser-control MCP serv ...[truncated 335 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace chrome-devtools-mcp@latest with an exact, reviewed version such as chrome-devtools-mcp@X.Y.Z.
  2. Install the dependency in a controlled project with a committed lockfile instead of downloading it dynamically during gateway startup.
  3. Verify package provenance, publisher identity, release signatures, and integrity hashes before installation.
  4. Use an internal package mirror or approved artifact repository that retains reviewed versions.
  5. Configure automated dependency scanning and require security review before upgrading the pinned version.
  6. Run the MCP server under a dedicated, minimally privileged operating-system account or sandbox.
  7. Prevent unnecessary network access from the MCP process after installation where operationally feasible.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Browser-Wide Remote Debugging Exposes Unrelated Authenticated Tabs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-22, 65-75, 104-119
Vulnerability Type: Excessive browser access and insufficient session isolation
Risk Level: Medium

Vulnerable Instructions and Tool Calls

text
Server running at: 127.0.0.1:9222
text
chrome-devtools__list_pages
browser(action="tabs")
browser(action="navigate", targetId=...)
browser(action="snapshot")
browser(action="act", request={kind:"click", ref:...})
text
browser(action="tabs")
browser(action="open", url="https://outlook.cloud.microsoft/mail/")

Technical Analysis

The Skill instructs the user to enable Chrome remote debugging and then allows the MCP or browser tool to enumerate and control browser tabs. The documented functionality is intended to read Outlook email, but the debugging interface is attached to the user's general local Chrome session rather than an isolated browser profile dedicated to Outlook.

Tab enumeration, navigation, snapshots, form filling, and clicking are browser-wide capabilities. They can expose unrelated authenticated services open in the same debugging-enabled browser. Binding the debugging endpoint to 127.0.0.1 reduces remote network exposure, but it does not protect against untrusted or compromised processes running under the local user account.

The use of a logged-in Outlook tab is intentional and disclosed. The security weakness is the absence of least-privilege isolation between the required Outlook session and unrelated browser sessions.

Attack Path

  1. The user enables remote debugging for the ordinary Chrome instance.
  2. The same Chrome profile contains an authenticated Outlook session and may contain other authenticated tabs.
  3. The MCP component automatically connects to the debugging-enabled browser.
  4. The component calls list_pages or browser(action="tabs") to enumerate every exposed tab.
  5. A compromised dependency, malicious local pr ...[truncated 973 chars]
Remediation
View remediation

Remediation Suggestions

  1. Launch a dedicated Chrome instance and profile used exclusively for Outlook automation.
  2. Do not enable remote debugging on the user's primary browser profile.
  3. Close all unrelated tabs before connecting the MCP server.
  4. Use a dedicated operating-system account or sandbox for the automated browser where possible.
  5. Require explicit user confirmation before opening an email, reading its body, navigating away from Outlook, or interacting with any non-Outlook origin.
  6. Enforce an origin allowlist limited to approved Outlook domains.
  7. Reject tool operations targeting tabs whose URLs are outside the allowlist.
  8. Disable remote debugging immediately after the requested mail operation completes.
  9. Avoid exposing sensitive web applications concurrently in the debugging-enabled browser.
  10. Log tab selection, navigation, snapshot, and interaction operations so unauthorized scope expansion can be detected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger scope is broad enough that the skill could activate for generic 'check email' or Outlook-related requests without clearly constraining when mailbox access should occur. Because this skill drives a local browser session into a live mailbox, ambiguous activation increases the chance of unintended access to private communications and over-collection of sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables browser automation against an authenticated Outlook session and can read message lists and message bodies, but it does not prominently warn users that this grants access to highly privacy-sensitive mailbox contents. In this context, missing disclosure is especially dangerous because the skill operates on a local logged-in browser, so activation can expose emails, contacts, attachments, and other account data with minimal friction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The entire skill description and operational instructions are presented only in Chinese, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.